First published: Wed Nov 10 2021(Updated: )
XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted ico file. Related to a Read Access Violation starting at USER32!SmartStretchDIBits+0x33.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xnview Xnview Mp | <=0.96.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-23887.
The severity of CVE-2020-23887 is classified as medium with a severity value of 5.5.
XnView MP version 0.96.4 is the affected software for CVE-2020-23887.
CVE-2020-23887 allows attackers to cause a denial of service (DoS) via a crafted ico file.
At the time of writing, there is no known fix available for CVE-2020-23887. It is recommended to update to the latest version of XnView MP when a fix becomes available.